ctprp Solved Correctly Latest Update 2027, Graded A+
Question 1.
third party
Correct Answer: entities or persons that work on behalf of the organization but
are not its employees, including consultants, contingent workers, clients,
business partners, service providers, subcontractors, vendors, suppliers,
affiliates and any other person or entity that accesses customer, company
confidential/proprietary data and/or systems that interact with that data
Question 2.
third party access to company data/systems
Correct Answer: it presents unique risks due to the inability to directly address
how they control access to those systems and data
Question 3.
TPRM
Correct Answer: a process for identifying and managing the risks created when
hiring a third party to provide goods and/or services. it's primary focus is usually
on data protection/privacy and IT security controls, but its scope depends
entirely on the nature of the services provided by the third party. therefore, it
may include operational issues such as business continuity and disaster
recovery, financial integrity, regulatory compliance, the vendors own third party
risk management practices
Question 4.
Requirements for third party oversight
Correct Answer: - relationships between organization and vendors has become
more complicated as vendors are being viewed as business partners
- risks associated with working with vendors have become complicated as those
vendors have been more popular targets for cyber attacks
- regulatory environment is more complex
- vendors are targeted by criminals
Question 5.
governance model/structure to manage third party risk
Correct Answer: - define clear roles and responsibility
- risk management framework to focus approach
- "right-size" structure based on risk
,Question 6.
first line of defense
Correct Answer: business who use the outsourced services. business unit
managers control the vendor relationship and may serve as primary contact for
gathering assessment due diligence and ensure remediation is complete. they
have ownership of risks the business unit will accept
Question 7.
second line of defense
Correct Answer: compromised of the groups within the company who provide
risk oversight (risk management, compliance, legal, etc). they establish policies,
procedures, controls for managing risk and provide oversight/guidance for the
first line
Question 8.
third line of defense
Correct Answer: internal/external audit provide validation for the risk and
control assessments established by the second line
Question 9.
policies
Correct Answer: defined at enterprise level and include all relevant corporate
functions
Question 10.
standards
Correct Answer: corporate standards for risk tiers, rating, classifications and all
regulatory/industry guidelines to be followed
Question 11.
procedures
Correct Answer: "what" you're supposed to do to implement the policies
Question 12.
criteria for risk tiers will be used to establish
Correct Answer: - contract requirements
- level/type of assessment
- frequency of assessment
, Question 13.
third party contract
Correct Answer: it defines entire relationship with vendor and establishes the
rights, roles and responsibilities, including ability to assess an require
remediation form vendor
Question 14.
jwhich areas of the company should be involved
Correct Answer: - business unit
- it
- procurement
- security
- legal
- disaster recovery/BCP
- support - call center/shared services
Question 15.
how to ensure contract provisions is consistent with vendor risk rank
Correct Answer: - validate contracts are aligned with vendor risk rank
- standards for vendor ranks should be based on corporate risk tolerance
Question 16.
criteria for contract review cycle
Correct Answer: - periodic contract review should be developed based on vendor
rank
- review is required when there are triggers (breach, merger, regulatory change,
etc)
Question 17.
procedures to review existing contracts
Correct Answer: - to ensure they comply with current standards (renewal,
revisions, incident, etc)
- a remediation process to correct the contract deficiencies
Question 18.
standards for vendor outsourcing (fourth parties)
Correct Answer: - prior notice and permission
- risk assessment performed (and periodically)
- third party should have their own VRM program
Question 1.
third party
Correct Answer: entities or persons that work on behalf of the organization but
are not its employees, including consultants, contingent workers, clients,
business partners, service providers, subcontractors, vendors, suppliers,
affiliates and any other person or entity that accesses customer, company
confidential/proprietary data and/or systems that interact with that data
Question 2.
third party access to company data/systems
Correct Answer: it presents unique risks due to the inability to directly address
how they control access to those systems and data
Question 3.
TPRM
Correct Answer: a process for identifying and managing the risks created when
hiring a third party to provide goods and/or services. it's primary focus is usually
on data protection/privacy and IT security controls, but its scope depends
entirely on the nature of the services provided by the third party. therefore, it
may include operational issues such as business continuity and disaster
recovery, financial integrity, regulatory compliance, the vendors own third party
risk management practices
Question 4.
Requirements for third party oversight
Correct Answer: - relationships between organization and vendors has become
more complicated as vendors are being viewed as business partners
- risks associated with working with vendors have become complicated as those
vendors have been more popular targets for cyber attacks
- regulatory environment is more complex
- vendors are targeted by criminals
Question 5.
governance model/structure to manage third party risk
Correct Answer: - define clear roles and responsibility
- risk management framework to focus approach
- "right-size" structure based on risk
,Question 6.
first line of defense
Correct Answer: business who use the outsourced services. business unit
managers control the vendor relationship and may serve as primary contact for
gathering assessment due diligence and ensure remediation is complete. they
have ownership of risks the business unit will accept
Question 7.
second line of defense
Correct Answer: compromised of the groups within the company who provide
risk oversight (risk management, compliance, legal, etc). they establish policies,
procedures, controls for managing risk and provide oversight/guidance for the
first line
Question 8.
third line of defense
Correct Answer: internal/external audit provide validation for the risk and
control assessments established by the second line
Question 9.
policies
Correct Answer: defined at enterprise level and include all relevant corporate
functions
Question 10.
standards
Correct Answer: corporate standards for risk tiers, rating, classifications and all
regulatory/industry guidelines to be followed
Question 11.
procedures
Correct Answer: "what" you're supposed to do to implement the policies
Question 12.
criteria for risk tiers will be used to establish
Correct Answer: - contract requirements
- level/type of assessment
- frequency of assessment
, Question 13.
third party contract
Correct Answer: it defines entire relationship with vendor and establishes the
rights, roles and responsibilities, including ability to assess an require
remediation form vendor
Question 14.
jwhich areas of the company should be involved
Correct Answer: - business unit
- it
- procurement
- security
- legal
- disaster recovery/BCP
- support - call center/shared services
Question 15.
how to ensure contract provisions is consistent with vendor risk rank
Correct Answer: - validate contracts are aligned with vendor risk rank
- standards for vendor ranks should be based on corporate risk tolerance
Question 16.
criteria for contract review cycle
Correct Answer: - periodic contract review should be developed based on vendor
rank
- review is required when there are triggers (breach, merger, regulatory change,
etc)
Question 17.
procedures to review existing contracts
Correct Answer: - to ensure they comply with current standards (renewal,
revisions, incident, etc)
- a remediation process to correct the contract deficiencies
Question 18.
standards for vendor outsourcing (fourth parties)
Correct Answer: - prior notice and permission
- risk assessment performed (and periodically)
- third party should have their own VRM program